OpenFolksDocs
Security

Permissions and secrets

Approvals, operating-system grants, and provider credentials.

Approval cards

Supported engines emit permission requests and questions through the harness. OpenFolks shows them inline and records the outcome. Cancellation closes outstanding requests so stale approvals cannot be answered after a turn has ended.

“Always allow” is narrow: it is tied to a server-issued key and a pending request. It does not grant arbitrary execution.

Operating-system permissions

Screen Recording and Accessibility are controlled by the OS. The desktop process owns local CUA lifecycle so grants are attributed to OpenFolks.

Secret handling

  • Do not paste API keys into chat.
  • Packaged builds use write-only settings and operating-system-backed encryption where supported.
  • Secret values are scrubbed from public configuration responses.
  • Per-provider environment injection keeps unrelated engine processes from inheriting credentials they do not use.
  • OAuth tokens for connected apps stay with Composio.

Shared machines

OpenFolks assumes the logged-in OS user owns the workspace. On a shared machine, other administrators may read application data or inspect processes. Use a dedicated OS account for stronger separation.

On this page